Impact
Inefficient JSON parsing in hMailServer causes a quadratic time complexity when handling objects with duplicate member names. An attacker can craft a 16 MB JSON payload and deliver it via a TLS‑RPT report or the webmail REST API, forcing the server to search already‑read members and consuming a delivery or API worker thread for minutes. Because the processing thread remains busy, the server stops delivering any mail, both inbound and outbound, for an hour per report, effectively denying service to all users.
Affected Systems
All versions of Progressive Robot Ltd.’s hMailServer released before 6.3.6 contain the flaw; the patch in 6.3.6 keeps member names in a hash set and parses JSON in one pass. The vulnerability affects any hosted domain that has TLS‑RPT reports enabled and any webmail REST endpoint that accepts JSON bodies larger than 64 KB.
Risk and Exploitability
The CVSS score of 7.5 denotes a high impact denial‑of‑service scenario. EPSS is not available, but the exploit requires only a crafted email or REST request, no authentication, and can be performed remotely. The flaw is not listed in the CISA KEV catalog, yet the risk remains significant for organizations that rely on TLS‑RPT reports or the REST API for mail handling.
OpenCVE Enrichment